Sign in

Sebastian Silbermann

@sebbie.dev
1.1K followers 183 following 59 posts

nextjs @vercel.com, @react.dev at night, @testing-library.com core | testing + a11y first | he/him

PostsRepliesMedia
Reposted by Sebastian Silbermann
Next.js @nextjs.org · 6h
The September Next.js security release is now available. It addresses seven vulnerabilities, including one high-severity issue. Upgrade now: ▲ ~/ npm install next@16.3.8 ▲ ~/ npm install next@15.5.27 nextjs.org/blog/septem...
nextjs.org
September 2026 Security Release
The September 2026 security release for Next.js is now available
173
Sebastian Silbermann @sebbie.dev · 09/09/2026
Almost as many contributors as 19.0.0. Lots of bug fixes from the community in there!
070
Reposted by Sebastian Silbermann
Devon Govett @devongovett.me · 01/09/2026
New React Aria release! 🧭 New NavigationTree component, perfect for sidebars. Supports expandable items, sections, keyboard navigation, action buttons, etc. ⌛️ Menu async load more 📝 TokenField selection updates 📱 iOS overlay positioning fixes react-aria.adobe.com/releases/v1-...
Screenshot of NavigationTree showing a list with Home, Files expanded with Photos and Videos nested, and Shared which is not expanded. Each item has an action menu.
0223
Reposted by Sebastian Silbermann
Carlo Zottmann @zottmann.dev · 29/08/2026
💯 > Blaming #GDPR for the cookie banner is like blaming the health inspector for the roaches. The banner is deliberate vandalism, a dark pattern engineered to exhaust you before you can learn anything about the #surveillance apparatus humming behind the "OK." matduggan.com/you-know-gdp... #privacy
matduggan.com
You Know GDPR Is Good Based on Who Hates It
FDR has always been one of my favorite presidents, second maybe to Lincoln. Both were men the establishment assumed were one of them until, to their horror, they governed like they weren't. Both could...
15313
Reposted by Sebastian Silbermann
Next.js @nextjs.org · 25/08/2026
The August Next.js security release is now available one day ahead of schedule to include a fix for a newly disclosed vulnerability in an upstream dependency. ▲ ~/ npm install next@16.3.3 ▲ ~/ npm install next@15.5.24 nextjs.org/blog/august...
nextjs.org
August 2026 Security Release
The August 2026 security release for Next.js is now available
1132
Sebastian Silbermann @sebbie.dev · 21/08/2026
it is specifically for Transitions. With what other function should it be collapsed? Keep in mind that you can have multiple optimistic states for a Transition.
110
Sebastian Silbermann @sebbie.dev · 20/08/2026
For those use cases React has useOptimistic: react.dev/reference/re...
130
Reposted by Sebastian Silbermann
Next.js @nextjs.org · 03/08/2026
Next.js 16.3 is now available! • Up to 90% less memory in dev • Faster builds, type checking, and rendering • Better tooling for AI agents • Custom error boundaries • Instant Navigations for SPA-like responsiveness nextjs.org/blog/next-16-3 Here's what's new ↓
4767
Reposted by Sebastian Silbermann
Next.js @nextjs.org · 21/07/2026
Following our move to scheduled, pre-announced security updates, the July release is out. This release addresses several security issues in Next.js 16 and 15. Update to 16.2.11 (Active LTS) or 15.5.21 (Maintenance LTS) now. nextjs.org/blog/july-2... x.com/nextjs/stat...
nextjs.org
July 2026 Security Releases
The July 2026 security releases for Next.js are now available
2153
Sebastian Silbermann @sebbie.dev · 19/07/2026
Can't a clanker have some fun frolicking around while we're tabbed out doomscrolling social media?
130
Sebastian Silbermann @sebbie.dev · 17/07/2026
Turbopack didn't start from a generalized place. It started as Webpack and then was generalized into Turbopack. That's where the original "Webpack successor" framing came from.
010
Reposted by Sebastian Silbermann
dan @danabra.mov · 16/07/2026
wrote some thoughts on turbopack github.com/vercel/next....
github.com
Next.js development high memory usage · Issue #54708 · vercel/next.js
Before posting a comment on this issue please read this entire post. Previous work The past few weeks we've been investigating / optimizing various memory usage issues. Specifically geared towards ...
4424
Reposted by Sebastian Silbermann
Ivan Akulov @iamakulov.com · 15/07/2026
Possibly one of the most impressive Safari bugs I’ve run into lately: Going back (with a swipe) in *any* React app that uses Navigation API freezes the page for three seconds. What’s fun is the main thread is not frozen, only the rendered page is.
3615
Reposted by Sebastian Silbermann
Next.js @nextjs.org · 14/07/2026
Going forward, Next.js will be making security releases more predictable by announcing them ahead of time. More details: nextjs.org/blog/next-s...
nextjs.org
Next.js Security Release and Our Next Patch Release
Next.js is moving to a formal security release process
1255
Reposted by Sebastian Silbermann
Aurora Scharff @aurorascharff.no · 09/07/2026
I've been working on the React Suspense docs: there's now a full list of what activates a Suspense boundary, with a live example for each trigger. Thanks @danabra.mov and Sebbie Silbermann for reviews! react.dev/reference/re... Demos below ↓
react.dev
<Suspense> – React
The library for web and native user interfaces
2726
Reposted by Sebastian Silbermann
Max @maxwellcohen.bsky.social · 09/07/2026
The Suspense is over! The newly updated Suspense docs now show the 7 ways of updating suspense boundaries, what a Suspense-enabled framework is, and lots of examples! Thank you to @aurorascharff.no for writing, and @sebbie.dev, @danabra.mov and @yadiel.dev for reviewing! react.dev/reference/re...
react.dev
<Suspense> – React
The library for web and native user interfaces
1325
Reposted by Sebastian Silbermann
tierney cyren @bnb.im · 04/07/2026
it is incredibly stupid to generate blog posts with llms anyone can output the same thing with the same prompts. If they’re interested in reading that, let them write the prompts. if it’s a writing skill issue on your end… failing at writing is how you get better at writing.
2524
Reposted by Sebastian Silbermann
Aurora Scharff @aurorascharff.no · 22/06/2026
Cache Components surface errors as you build when something dynamic would block your shell, nudging you toward a more performant app. The shell loads instantly while dynamic parts stream, and on this demo every route lands in the green. We're working hard to make them easier to adopt!
1124
Reposted by Sebastian Silbermann
rich harris @rich-harris.dev · 10/06/2026
There are two ways to resolve the cognitive dissonance of being on Twitter while also caring about all the awful shit happening because of Twitter 1. Leave Twitter 2. Stop caring Profoundly disappointing how many people I like seem to have chosen the latter
1446180
Reposted by Sebastian Silbermann
Aurora Scharff @aurorascharff.no · 26/05/2026
I'm going on tour with the Next.js team in June! Coming to Amsterdam and London to share what's new in Next.js 16.3, hang out with the community, and answer your questions. • June 9: San Francisco: luma.com/vercel-408x • June 11: Amsterdam: luma.com/34nqdfc3 • June 18: London: luma.com/lfr946sc
1142
Reposted by Sebastian Silbermann
Cassie Evans @cassiecodes.bsky.social · 26/05/2026
I'm so tired of being expected to read things that no one has bothered to write.
241393165
Sebastian Silbermann @sebbie.dev · 12/05/2026
If you treat your default branch as something that went through PR review, you better make sure your workflow_dispatch doesn't do a checkout with a custom input.
010
Sebastian Silbermann @sebbie.dev · 12/05/2026
I personally would recommend reviewing actions/checkout with a custom ref input instead. actions/checkout is the way to escape trust boundaries. In pull_request_target events that's fork -> upstream. But in workflow_dispatch events actions/checkout allows running in protected GH environments.
100
Reposted by Sebastian Silbermann
Next.js @nextjs.org · 26/03/2026
Next.js is used by millions of developers across every major cloud. Making it work well everywhere is on us. Here's what we've built with Netlify, Cloudflare, OpenNext, AWS, and Google Cloud, and the commitments we're making. nextjs.org/nextjs-acro...
nextjs.org
Next.js Across Platforms: Adapters, OpenNext, and Our Commitments
Next.js 16.2 introduces a stable Adapter API, a public adapter test suite, and a working group for more consistent deployment across platforms.
0498
Reposted by Sebastian Silbermann
Nicolò Ribaudo @nicr.dev · 12/02/2026
The "export defer" TC39 proposal aims to introduce a similar optimization *at the language level*, so that you can rely on it in all the tools and environments that you might run your code with. Just because you need one thing from a module, you shouldn't pay the cost of all the others!
github.com
GitHub - tc39/proposal-deferred-reexports
Contribute to tc39/proposal-deferred-reexports development by creating an account on GitHub.
0388
Sebastian Silbermann @sebbie.dev · 10/02/2026
That information would you use from the component tree for a specific timeline entry? Do you need the whole tree or just the parent/owner stack?
100
Reposted by Sebastian Silbermann
Ricky @ricky.fm · 10/02/2026
Does this diagram help? It uses the React Performance Tracks to explain what React is doing, and what you'll see when you use the tracks: github.com/reactjs/reac...
3303
Reposted by Sebastian Silbermann
Barry Pollard @tunetheweb.com · 04/02/2026
From Chrome 145 (on general release next week!), DevTools we will start to show so called "soft" navigations and "Soft LCP" in the Performance Panel traces. These are for SPAs which don't do a full page load, but instead "fake it" by updating the current page and pushing a new history entry. 1/5 🧵
Screenshot of a performance trace in Chrome DevTools with a few additional "Nav*" and "LCP*" markers. Hovering over the "LCP*" shows this is a "Soft LCP" and in the Summary panel when you click on it you see "Soft Largest Contentful Paint" and a "Learn more about Soft Largest Contentful Paint" link.
24512
Reposted by Sebastian Silbermann
Wyatt Johnson @wyattjoh.ca · 02/02/2026
Just ported my personal site over to @astro.build with a custom @bun.sh adapter I wrote 🚀 👋 I'm currently looking for my next role, so if you're hiring, reach out! - Astro + Bun for blazing fast SSR - Supports ISR and SWR - Hosted behind @cloudflare.social github.com/wyattjoh/ast...
github.com
GitHub - wyattjoh/astro-bun-adapter: Astro adapter for Bun with optimized static file serving and ISR (Incremental Static Regeneration)
Astro adapter for Bun with optimized static file serving and ISR (Incremental Static Regeneration) - wyattjoh/astro-bun-adapter
041
Reposted by Sebastian Silbermann
Maël Nison @mael.dev · 28/01/2026
It’s happening. Yarn 6 Preview is here 💫 Yes, we rewrote it in Rust 🦀⚡️ I'm incredibly excited for the future of our beloved package manager. See the benchmarks and plans in our latest post:
yarn6.netlify.app
Yarn 6 Preview
Yarn is a modern JavaScript package manager focused on speed, security, and reliability.
712526
Reposted by Sebastian Silbermann
Next.js @nextjs.org · 20/01/2026
Learn how we built Turbopack with incremental computation to scale development and builds to Next.js applications of all sizes. nextjs.org/blog/turbop...
nextjs.org
Inside Turbopack: Building Faster by Building Less
Learn how we built Turbopack with incremental computation to scale development and builds to massive Next.js applications.
0152
Reposted by Sebastian Silbermann
Matteo Collina @nodeland.dev · 13/01/2026
Upgrade now: Node.js 20.20.0 Node.js 22.22.0 Node.js 24.13.0 Node.js 25.3.0 Full technical deep dive in our blog post: nodejs.org/en/blog/vuln...
121
Reposted by Sebastian Silbermann
Federal Reserve @federalreserve.gov · 12/01/2026
Video message from Federal Reserve Chair Jerome H. Powell: www.youtube.com/watch?v=KckG... www.federalreserve.gov/newsevents/s...
youtube.com
Statement by Federal Reserve Chair Jerome H. Powell
YouTube video by Federal Reserve
1134238269100
Reposted by Sebastian Silbermann
Ryan Cavanaugh @searyanc.dev · 30/12/2025
Your TypeScript year in review You "silenced" 417 errors with `as any` that turned into runtime errors as soon as the code ran TypeScript printed 4,693 error messages. 26 of them made sense You spent 98 minutes waiting for tsc to run. During this time you spent 544 minutes reading social media
518217
Reposted by Sebastian Silbermann
Vercel @vercel.com · 19/12/2025
We paid $1 million to hackers to harden our firewall defenses. Today we're telling the story of how we strengthened our WAF, disclosing a runtime mitigation layer for the first time, and how we partnered with @Hacker0x01 to defend against React2Shell. vercel.com/blog/our-mi...
vercel.com
Our $1 million hacker challenge for React2Shell - Vercel
We paid $1M to security researchers to break our WAF. Here's what we learned defending against React2Shell.
1113
Reposted by Sebastian Silbermann
Sam Selikoff @samselikoff.com · 18/12/2025
Been working on a new microsite to teach Next.js patterns, and I just published a new one: "Sharing data with Client Components" See how to use promises to keep your page unblocked so it can be rendered (or prerendered) as early as possible. Enjoy! next-16-recipes.vercel.app/sharing-data...
0284
Sebastian Silbermann @sebbie.dev · 04/12/2025
which PRs? I can take a look next week.
140
Reposted by Sebastian Silbermann
Daishi Kato @daishikato.com · 04/12/2025
⛩️ Waku v0.27.3 has been released. - Dependency updates addressing the critical React Server Components security vulnerability - Various small improvements All users should update immediately: github.com/wakujs/waku/...
github.com
Update instructions for CVE-2025-55182 · wakujs waku · Discussion #1823
References https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components https://www.facebook.com/security/advisories/cve-2025-55182 GHSA-fv66-9v8q-g76r Affected vers...
0215
Reposted by Sebastian Silbermann
React @react.dev · 03/12/2025
There is critical vulnerability in React Server Components disclosed as CVE-2025-55182 that impacts React 19 and frameworks that use it. A fix has been published in React versions 19.0.1, 19.1.2, and 19.2.1. We recommend upgrading immediately. react.dev/blog/2025/12...
react.dev
Critical Security Vulnerability in React Server Components – React
The library for web and native user interfaces
714691
Reposted by Sebastian Silbermann
dan @danabra.mov · 26/11/2025
fantastic explanation by @storyhb.com, also maybe first example i remember of a feature being more immediately useful (in a sense) self-hosted compared to serverless/vercel
github.com
Next 16.0: "Use cache" is ignored in dynamic routes · Issue #85240 · vercel/next.js
Link to the code that reproduces this issue https://github.com/leo-cheron/next16-cache To Reproduce Create a Next.js 16 app with dynamic routes (e.g., app/[locale]/page.tsx) File: app/[locale]/page...
3203
Sebastian Silbermann @sebbie.dev · 19/11/2025
It's working for me now
110
Reposted by Sebastian Silbermann
dan @danabra.mov · 10/11/2025
i'm looking for a new job
overreacted.io
Hire Me in Japan — overreacted
I'm looking for a new job.
31395111
Reposted by Sebastian Silbermann
P(aul) Frazee @pfrazee.com · 04/11/2025
One of the huge perks of working at a software company is, when there's something about the product that bothers you personally, you can get your hands dirty and find out why it's basically impossible to get fixed
29908108
Reposted by Sebastian Silbermann
Python Software Foundation @python.org · 27/10/2025
TLDR; The PSF has made the decision to put our community and our shared diversity, equity, and inclusion values ahead of seeking $1.5M in new revenue. Please read and share. pyfound.blogspot.com/2025/10/NSF-... 🧵
python.org
The official home of the Python Programming Language
12363792728
Reposted by Sebastian Silbermann
Next.js @nextjs.org · 22/10/2025
Next.js 16 • Cache Components • Turbopack enabled by default • Turbopack file system caching (beta) • Optimized navigations and prefetching • Improved caching APIs • Build Adapters API (alpha) • React 19.2 nextjs.org/blog/next-16
36516
Reposted by Sebastian Silbermann
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 21/10/2025
I am awarded a gold medal by the Royal Swedish Academy of Sciences for my work on #curl daniel.haxx.se/blog/2025/10/21/a-ro…
daniel.haxx.se
A royal gold medal
_The Royal Swedish Academy of Sciences_ (IVA, the same org that selects winners for three of the Nobel prize categories) awards me a gold medal 2025 for my work on curl. This academy, established 1919 by the Swedish king Gustav V, has been awarding _great achievers_ for over one hundred years and the simple idea behind the awards is, as quoted from their website: > Gold medals are awarded every year to people who, through outstanding deeds, have contributed to creating a better society. I am of course humbled and greatly honored to have been selected as a receiver of said award this year. To be recognized as someone who **have contributed to creating a better society** , selected by top people in competition with persons of remarkable track records and achievements. Not too shabby for a wannabe-engineer like myself who did not even attend university. There have been several software and tech related awardees for this prize before, but from what I can tell I am the first Open Source person to receive this recognition by the academy. ## Justification The Academy’s justification is given in Swedish (see below) but it should be translated roughly like this: _System developer Daniel Stenberg is awarded the IVA Gold Medal for his contributions to software development, where he has been central to internet infrastructure and free software. Through his work with curl, the tool that is now used by billions of devices worldwide, he has enabled reliable and secure data transfer over the internet. Not just between programs in traditional computers, but everything from smartphones and cars, to satellites and spacecraft._ The original Swedish “motivering”: _Systemutvecklare Daniel Stenberg tilldelas IVAs Guldmedalj för sina insatser inom mjukvaruutveckling där han haft en central betydelse för internetinfrastruktur och fri programvara. Genom sitt arbete med curl, verktyget som i dag används av miljarder enheter världen över, har han möjliggjort tillförlitlig och säker dataöverföring över internet. Inte bara mellan program i traditionella datorer utan allt från smartphones och bilar, till satelliter och rymdfarkoster._ ## The ceremony The associated award ceremony when the physical medal is handed over happens this Friday at the Stockholm City Hall‘s Blue Hall, the same venue used for the annual Nobel Prize banquet. I have invited my wife and my two adult kids to participate in those festivities. ## A _second_ medal indeed Did I not already receive a gold medal? Why yes, I did eight years ago. Believe me, it does not _get old_. This is something I can get used to. But yes: it is beyond crazy to get one medal in your life. Getting _two_ is simply incomprehensible. This is also my _third_ award received within this calendar year so I completely understand if you already feel bored by my blog posts constantly banging my own drum. See European Open Source Achievement Award and Developer of the year for the two previous ones. ## The medal I wanted to include a fine high resolution image of the medal in this post, but I failed to fine one. I suppose I will just have to make a few shots by myself after Friday and do a follow-up post!
2762110
Reposted by Sebastian Silbermann
Una Kravets @una.im · 14/10/2025
View transitions are in every browser now ✨
223444
Sebastian Silbermann @sebbie.dev · 09/10/2025
sounds like a rewrite not migration
110
Sebastian Silbermann @sebbie.dev · 09/10/2025
Do you have a PR to share?
110
Sebastian Silbermann @sebbie.dev · 09/10/2025
I don't know how a migration helper from a static json file the new flat config can fail so horribly. Does anybody have a successful migration story for a non-trivial .eslintrc.json to flat config?
340